Data Processing Agreement

Last updated: July 2025

1. Scope & Parties

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Colabe ("Processor") and the business entity using the Service ("Controller"). This DPA governs how Colabe processes personal data on behalf of the Controller in connection with the Service.

2. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person, as defined by applicable data protection laws.

"Processing" means any operation performed on Personal Data, including collection, storage, use, transfer, and deletion.

"Sub-processor" means a third party engaged by Colabe to process Personal Data on behalf of the Controller.

3. Data Processing Details

Categories of data subjects: business owners, employees, customers of the Controller's business.

Types of personal data: names, email addresses, phone numbers, addresses, transaction data, communication content, and device identifiers.

Purpose of processing: providing the Colabe platform services including AI-powered business operations, payment processing, customer communications, and analytics.

Duration: for the duration of the service agreement plus the data retention period outlined in the Privacy Policy.

4. Processor Obligations

Colabe processes Personal Data only on documented instructions from the Controller, ensures confidentiality, implements appropriate technical and organizational measures, assists with data subject requests, and deletes or returns Personal Data upon termination unless retention is legally required.

5. Sub-processors

Colabe may engage sub-processors to provide infrastructure, AI, communications, and payment services. Colabe remains responsible for sub-processor performance and requires materially equivalent data protection obligations.

The Controller may object to a new sub-processor within 14 days of notification. If the objection is not resolved, the Controller may terminate the agreement.

6. International Transfers

Where Personal Data is transferred outside the EU/EEA or the country of origin, Colabe ensures appropriate safeguards through EU Standard Contractual Clauses, adequacy decisions, or other legally recognized transfer mechanisms.

7. Security Measures

Colabe implements encryption in transit and at rest, access controls with role-based permissions, regular vulnerability assessments, backup and disaster recovery procedures, access logging, monitoring, and employee security training.

8. Data Breach Notification

In the event of a personal data breach, Colabe will notify the Controller within 72 hours of becoming aware and provide details required to support supervisory authority and data subject notifications where applicable.

9. Audits

Colabe makes available information necessary to demonstrate compliance with this DPA and applicable data protection laws. The Controller may conduct audits with reasonable notice and Colabe will cooperate with relevant requests.

10. Term & Termination

Upon termination, Colabe will, at the Controller's election, return or delete Personal Data within 30 days unless retention is required by applicable law.

11. Contact

For questions about this DPA, contact the Data Protection Officer at dpo@colabe.com.br.

Ready to get started?

Create your account and see Colabe organizing the operation with AI.